In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. guest
role users can self-register even when the admin does not allow it. This happens due to front-end restriction only.
{ "nvd_published_at": "2021-11-02T07:15:00Z", "cwe_ids": [ "CWE-285", "CWE-669", "CWE-863" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-11-03T14:44:37Z" }